This column indicates whether a rule has pending changes. Rules that are currently active on the Decoder have no indicator. If the rule is new or has been modified, the column contains . Once the rules are applied, the pending indicator is removed.

Name

This is the rule name, a descriptive identifier for the rule.

Condition

This is the definition of the condition that triggers an action when matched.

Packet Data

This column displays the Session Data action taken when a packet matches the rule. Possible values are Filter, Keep, or Truncate.

Alert

This column indicates whether the Decoder generates a custom alert when metadata matches the rule. Possible values are Enabled or Disabled.

Status

This column indicates whether the rule is enabled or disabled with a circle icon. If the circle is filled green, the rule is enabled. If the circle is empty, the rule is disabled.

The Rule Editor dialog provides the fields and options needed to define a network rule.

The following table describes the Rule Definition fields.

Field

Description

Rule Name

The descriptive name that identifies the rule.

Condition

The definition of the condition that triggers an action when matched. You can type directly in the field or build the condition in this field using meta from the Intellisense window actions. As you build the rule definition, Intellisense displays syntax errors and warnings.

In conditions, all string literals and time stamps must be quoted. Do not quote number values and IP addresses. Configure Decoder Rules provides additional details. This section also describes the meta keys that NetWitness Platform supports for use in network rule conditions.

The following table describes the Session Data actions.

Action

Description

Stop Rule Processing

If checked, further rule evaluation ends if the rule is matched, and the session is saved as indicated. If not checked, rule evaluation continues until all rules are evaluated.

Keep

The packet payload and associated meta are saved when they match the rule.

Filter

The packet is not saved when it matches the rule.

Truncate

The packet payload is not saved when it matches the rule, but packet headers and associated meta are retained.

The following table describes the session options.

Action

Description

Assemble

If checked, the assembler assembles the packet chain when it matches the rule.

Network Meta

The packet generates network metadata when it matches the rule.

Application Meta

The packet generates application metadata when it matches the rule.

Alert

The packet generates a custom alert when metadata matches the rule.

The following table describes Rule Editor dialog actions.

Action

Description

Reset

Resets the contents of the dialog to their values before editing; changes are discarded.

Cancel

Cancels any edits and closes the Rule Editor dialog.

OK

Saves the new rule or edited rule, and adds it to the rules grid. The Rule Editor dialog closes.